ValidMind
Type: company (AI-governance / model-risk-management & validation platform vendor) Sector: AI governance / model risk management & validation software, positioned for regulated banking and insurance First seen: 2026-07-02 Last updated: 2026-07-24
Created 2026-07-02 from ValidMind — Atryum (open-source agent control plane) & Agent Authority (June 2026) (daily AI-governance vendor-intelligence scan). Primary capability claims are the vendor’s own and not independently verified; prior mention exists in S-2026-04-17-fed-sr-26-2-mrm.
Updated 2026-07-24 based on S-2026-07-20-validmind-risk-tiering (daily AI-governance vendor-intelligence scan; primary vendor blog fetched) — ValidMind announced a Risk Tiering System (20 Jul 2026, shipping “with ValidMind’s end-July release”): governed, versioned risk-tier classification replacing free-text tier labels. Governance admins configure read-only, versioned Risk Tier Templates (Scorecard or Risk Matrix methods; weighted factors wired to inventory fields; hard-stop override rules); owners run Risk Tier Assessments that expose the full calculation chain and are flagged for reassessment if the template or underlying inventory data changes. Framed by the vendor against SR 26-2, SS 1/23, OSFI E-23 and the EU AI Act proportionate-classification expectations. Pre-GA at capture; no customer named; all claims vendor-asserted ⚠️.
Updated 2026-07-07 based on three scan items: two reference-customer case studies — an unnamed Fortune 500 US bank (five-month MRM-automation implementation, SR 11-7 framing) [S-2026-07-06-validmind-fortune500-bank-mrm] and Canada’s Department of Fisheries and Oceans (two-gate AI approval model, public sector) [S-2026-06-29-validmind-dfo-two-gate] — plus GAIG’s explanation of ValidMind’s absence from the inaugural Gartner MQ for AI Governance Platforms (attributed to multi-region inclusion criteria, not product quality — GAIG inference) [S-2026-06-22-gaig-gartner-mq-full-quadrant]. The reference-customer open question below is now partially answered: named/describable deployments exist (Canadian public sector; unnamed US bank), but still no named EU/UK regulated-FS reference.
Snapshot
ValidMind is an AI-governance and model-risk-management (MRM) platform vendor positioned natively for regulated financial services — its named industry solutions are Banking and Insurance, and it markets validation automation, AI/model risk unification and regulatory-evidence workflows [S-2026-06-15-validmind-atryum-agent-authority]. It sits on Paul’s MRM/validation and AI-governance watchlist and matters to the wiki because it is one of the few AI-governance vendors framing its offering around FS model-risk expectations (SR 11-7 / SR 26-2 lineage, SS1/23) rather than generic enterprise AI governance. In June 2026 it extended from model validation into runtime governance of autonomous agents [S-2026-06-15-validmind-atryum-agent-authority].
Positions / Claims they advance
- Launched Atryum (15 Jun 2026), an open-source runtime control plane for AI agents (GitHub; dual Apache-2.0 / Enterprise licence) that sits in the agent execution path, intercepts tool calls, evaluates whether an action is appropriate for the agent’s role/authority via policy-as-code, routes decisions to humans when needed, and keeps immutable audit trails (reasoning traces, tool-call logs, policy-evaluation records) [S-2026-06-15-validmind-atryum-agent-authority].
- Opened early access to ValidMind Agent Authority, a commercial enterprise layer on Atryum adding LLM-as-judge policy evaluation, user/group approval routing, agent-specific policy hierarchy, enterprise IAM integration and audit analytics — pitched as what “financial institutions need to operate agents at scale” (vendor framing) [S-2026-06-15-validmind-atryum-agent-authority].
- Positions its differentiator as governing agents “through your risk framework, not generic filters” — i.e. FS-native, policy-driven action authorization rather than credential/permission security (vendor claim, not independently verified) [S-2026-06-15-validmind-atryum-agent-authority].
- Announced a Risk Tiering System (20 Jul 2026; “rolls out with ValidMind’s end-July release”): centrally governed, versioned Risk Tier Templates (Scorecard with weighted factors and thresholds, or Risk Matrix; admin-defined tier vocabularies; hard-stop overrides) applied through Risk Tier Assessments that auto-pull inventory fields, expose the full calculation (inputs → component scores → factor results → weighting/thresholds → tier, including override triggers), assign the tier via a read-only field, preserve template version and publication history, and are flagged for reassessment when the methodology or underlying inventory data changes. Vendor’s stated aim: make risk classification defensible to supervisors (“a tier without its reasoning is difficult to challenge or defend”) under SR 26-2 / SS 1/23 / OSFI E-23 / EU AI Act proportionality expectations — vendor-asserted, pre-GA, no customer named [S-2026-07-20-validmind-risk-tiering].
- Prior recognition (context, stale >30 days, not re-reported as new): named Chartis RiskTech100 2026 No.1 AI Governance Platform (24 Feb 2026) and Model Validation Service of the Year; partners named include AWS, Experian, Snowflake and Databricks [S-2026-06-15-validmind-atryum-agent-authority].
Relationships
- relates-to → AI Governance Platforms — supplies an FS-native runtime action-authorization / policy-as-code control-plane layer within the agentic-governance sub-theme [S-2026-06-15-validmind-atryum-agent-authority].
- relates-to → Model Risk Management and Agentic AI — extends model validation/MRM into runtime control and evidence for autonomous agents [S-2026-06-15-validmind-atryum-agent-authority].
- relates-to → EU AI Act — immutable logging and human-routing bear on Art. 12 record-keeping and Art. 14 human-oversight expectations [inference].
Tracked changes
- 2026-07-20 — Announced the Risk Tiering System (governed, versioned risk-tier templates + explainable assessments across models/applications/agents/use cases), shipping with the end-July 2026 release; explicitly framed against SR 26-2, SS 1/23, OSFI E-23 and the EU AI Act [S-2026-07-20-validmind-risk-tiering].
- 2026-06-15 — Launched Atryum (open-source agent control plane) and opened early access to Agent Authority (enterprise layer for financial institutions) [S-2026-06-15-validmind-atryum-agent-authority].
- 2026-06-16/17 (reported 2026-06-22) — Absent from the inaugural Gartner MQ for AI Governance Platforms despite Chartis Category Leader / RiskTech100 2026 #1 status; GAIG attributes the absence “most likely” to Gartner’s multi-region inclusion requirement (>10 paid deployments across >2 regions) rather than product quality — GAIG’s inference, not a Gartner statement [S-2026-06-22-gaig-gartner-mq-full-quadrant].
- 2026-06-29 — Published (Dataversity) a case study of Canada’s Department of Fisheries and Oceans: two-gate approval model (use-case evaluation → product review) with continuous post-deployment monitoring; vendor-partnered content, public sector, non-FS [S-2026-06-29-validmind-dfo-two-gate].
- 2026-07-06 (surfaced) — Case study of an unnamed Fortune 500 US bank replacing fragmented manual AI-governance processes with ValidMind’s MRM platform in five months — centralised model inventory, lifecycle traceability, automated audit-ready documentation, framed against SR 11-7 examination pressure; vendor-published, bank unnamed, possibly the same deployment as a similar 20 June item [S-2026-07-06-validmind-fortune500-bank-mrm].
Open Questions
- Does a versioned Risk Tier Assessment record satisfy SR 26-2 / SS 1/23 effective-challenge expectations in an examination, or does defensibility still hinge on the quality of the override/expert-judgement usage the tool permits? And how does a firm-configurable scorecard coexist with the EU AI Act’s statutory (Annex III) classification tests? [S-2026-07-20-validmind-risk-tiering]
- Will the Risk Tiering System ship as described in the end-July release, and will any regulated customer be named using it? [S-2026-07-20-validmind-risk-tiering]
- No named EU/UK regulated-FS reference deployment of Atryum or Agent Authority is disclosed. (Partially updated 2026-07-07: ValidMind now publicises an unnamed Fortune 500 US bank MRM deployment and a Canadian public-sector governance-design engagement — but both are vendor-published, the bank is unnamed, and the EU/UK regulated-FS gap remains [S-2026-07-06-validmind-fortune500-bank-mrm][S-2026-06-29-validmind-dfo-two-gate].)
- Are the 6 July and 20 June “Fortune 500 bank” AIGI items the same underlying deployment or two? [S-2026-07-06-validmind-fortune500-bank-mrm]
- Whether Atryum/Agent Authority immutable logs and policy-evaluation records meet EU AI Act Art. 12 / Art. 14, SS1/23, SR 11-7 / SR 26-2 or DORA evidentiary thresholds, or remain a control concept short of an audit-ready evidence format (vendor-asserted).
- Whether a first-line vendor-operated control plane that governs and logs agent actions can supply second-line-acceptable assurance, or only first-line tooling that itself needs independent challenge under SS1/23.
- How ValidMind’s runtime action-authorization relates to “least agency / behavioural authorization” (Zenity) and data-layer access controls (Cyberhaven/Collibra) — complementary or overlapping layers.
Sources
- ValidMind — Atryum (open-source agent control plane) & Agent Authority (June 2026)
- S-2026-07-06-validmind-fortune500-bank-mrm — Fortune 500 US bank MRM-automation case study (via AIGI; low authority, vendor-published, bank unnamed).
- S-2026-06-29-validmind-dfo-two-gate — Canada DFO two-gate governance case study (via AIGI; low authority, vendor-partnered, public sector).
- S-2026-06-22-gaig-gartner-mq-full-quadrant — GAIG analysis explaining ValidMind’s absence from the inaugural Gartner MQ (medium authority, secondary).
- S-2026-07-20-validmind-risk-tiering — Risk Tiering System feature announcement (medium authority; primary vendor blog fetched directly, pre-GA, vendor-asserted).